Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown
CVE-2023-25495
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured
0
Attacker Value
Unknown
CVE-2023-29058
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
0
Attacker Value
Unknown
CVE-2023-29057
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
0
Attacker Value
Unknown
CVE-2022-34888
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.
0
Attacker Value
Unknown
CVE-2022-34884
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
0
Attacker Value
Unknown
CVE-2021-3942
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
0
Attacker Value
Unknown
CVE-2021-34991
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. When parsing the uuid request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14110.
0
Attacker Value
Unknown
CVE-2020-28419
Disclosure Date: November 09, 2021 (last updated October 07, 2023)
During installation with certain driver software or application packages an arbitrary code execution could occur.
0
Attacker Value
Unknown
CVE-2020-28899
Disclosure Date: March 16, 2021 (last updated February 22, 2025)
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
0
Attacker Value
Unknown
CVE-2011-3269
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
0